chiprook
← Security
SecuritySeptember 30, 2026, 11:20

LightLLM hit by two CVSS 9.8 unauthenticated RCE flaws

Two unauthenticated CVSS 9.8 RCE vulnerabilities (CVE-2026-103040 and CVE-2026-103041) were found in the LightLLM serving framework via pickle deserialization in RPyC services, plus a 7.5-rated DoS (CVE-2026-103042). No patch is confirmed and all versions through 1.2.0 are affected.

LightLLM hit by two CVSS 9.8 unauthenticated RCE flaws
#LightLLM
Read next
Security

F5 patches exploited CVSS 9.8 flaw in BIG-IP APM

Security

SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE

Security

Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites

Security

SolarWinds Patches Two Critical RCE Flaws in Observability Self-Hosted